VulnSea

imagemagick has 15 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 11 in the last 90 days against 2 in the 90 before. The busiest recent month was September 2026 with 11. The median CVSS is 3.7 (low). None have a confirmed exploitation report. The dominant weakness classes are CWE-400 (4) and CWE-416 (4).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
3.7
Publish → KEV
Last 90 days
11 prev 2

Products

  • ImageMagick 15
15
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

imagemagick vulnerabilities

CVEs affecting imagemagick, newest first. Open any entry for full detail, references, and exploit status.

15 CVEsRSS

CVE-2026-93588Low· 3.1
4d ago

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder reaches a memory (resource) limit at a specific point during processing, the failed allocation is not handled and a NUL…

SunlitImageMagick · ImageMagickEPSS 0.26%via NVD
CVE-2026-93586Low· 2.9
4d ago

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may result in a limited availability impact (e.g., a cra…

SunlitImageMagick · ImageMagickEPSS 0.11%via NVD
CVE-2026-93587Low· 3.3
4d ago

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific command line option is supplied, the decoder does not check a configured resource…

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific command line option is supplied, the decoder does not check a configured resource…

SunlitImageMagick · ImageMagickEPSS 0.11%via NVD
CVE-2026-93590Low· 3.7
4d ago

ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels

ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially crafted …

SunlitImageMagick · ImageMagickEPSS 0.31%via NVD
CVE-2026-93589Low· 3.7
4d ago

ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder

ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded causes a divide-by-zero and crashes the encoder, resulting in a denial of …

SunlitImageMagick · ImageMagickEPSS 0.29%via NVD
CVE-2026-86425Low· 3.3
2w ago

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted list of images can trigger memory access after deallocation, result…

Sunlitimagemagick · imagemagickEPSS 0.15%via NVD
CVE-2026-86424Low· 2.5
2w ago

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlin…

Sunlitimagemagick · imagemagickEPSS 0.11%via NVD
CVE-2026-86422Low· 3.3
2w ago

ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions

ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows that allows attackers to bypass read or write restrictions by exploiting symlink race conditions. Attackers can swap sym…

Sunlitimagemagick · imagemagickEPSS 0.10%via NVD
CVE-2026-86420Low· 3.7
2w ago

ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails

ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service.

Sunlitimagemagick · imagemagickEPSS 0.32%via NVD
CVE-2026-86423Low· 3.3
2w ago

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList method of PerlMagick

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList method of PerlMagick. A crafted call to the GetList method can trigger the use-after-free, resulting in a crash (denial of…

Sunlitimagemagick · imagemagickEPSS 0.11%via NVD
CVE-2026-86421Low· 3.7
2w ago

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service.

Sunlitimagemagick · imagemagickEPSS 0.44%via NVD
CVE-2026-56379High· 8.1
3mo ago

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector G…

Twilightimagemagick · imagemagickEPSS 0.88%via NVD
CVE-2026-56371Medium· 5.3
3mo ago

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each…

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each…

Sunlitimagemagick · imagemagickEPSS 0.26%via NVD
CVE-2026-23876High· 8.1
8mo ago

ImageMagick is free and open-source software used for editing and manipulating digital images

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an attacker to w…

Twilightimagemagick · imagemagickEPSS 0.66%via NVD
CVE-2025-65955Medium· 4.9
9mo ago

ImageMagick is free and open-source software used for editing and manipulating digital images

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked wi…

Sunlitimagemagick · imagemagickEPSS 0.16%via NVD
imagemagick vulnerabilities (CVEs) · VulnSea